On 26/08/2014 22:52, Henri Gomez wrote:
> Hi all
> 
> Are you aware SonarQube is analysing Tomcat in Nemo for years ?
> 
> 
> http://nemo.sonarqube.org/dashboard/index/50544
> 
> 310 Blocker issues, 121 Critical issues.

I took a quick look. The first 60 or so blocker issues I looked at were
all false positives triggered by us catching Throwable for good reasons.
Can we get a login to this system to make them as false positives?

Mark


> 
> Wondering if Coverity will provides more informations than SonarQube ?
> 
> BTW, SonarQube is analysing major ASF projects for a long time now :)
> 
> 
> 2014-08-26 11:20 GMT+02:00 Mark Thomas <ma...@apache.org>:
>> All,
>>
>> I have been pinged off-list by Coverity to say that they have set up
>> Tomcat with a free account with their static code analysis service.
>>
>> I think I have the ability to send invitations so if anyone wants to
>> take a look at the results, just reply here.
>>
>> I have taken a quick look and they do appear to have found some valid
>> threading issues. There are ~350 issues in total and I don't yet have a
>> feel for the false positive rate.
>>
>> Mark
>>
>> ---------------------------------------------------------------------
>> To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
>> For additional commands, e-mail: dev-h...@tomcat.apache.org
>>
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
> For additional commands, e-mail: dev-h...@tomcat.apache.org
> 


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to